▲ Korea National Diplomatic Academy
The online education system of the Korea National Diplomatic Academy, under the Ministry of Foreign Affairs, has been compromised by a hacking attack that lasted for approximately 10 months. It has been revealed that the server contained about 10,000 records of personal information belonging to former and current diplomats, as well as government officials dispatched to the academy.
The government is conducting an analysis without ruling out the possibility that the attack was carried out by a hacking organization backed by a foreign state.
According to the Ministry of Foreign Affairs, the system was introduced in 2022 during the COVID-19 pandemic to address difficulties in conducting in-person training for foreign service personnel.
The Ministry stated that it was notified by relevant agencies of abnormal access to the system in February of this year. Following the notification, the Ministry blocked the system and has been conducting an investigation in cooperation with relevant authorities.
It was found that the attacker gained control of the server between April and May of last year and maintained access until February of this year.
This means that an unidentified attacker had intermittent access to the site for approximately 10 months.
A Ministry of Foreign Affairs official stated, "There are difficulties in determining the exact details and scale of the data breach," but added that "10,000 records related to trainees were stored on the server."
The stored information reportedly included names, user IDs, email addresses, and encrypted passwords, and it is known that job titles and affiliations could also be inferred from the data.
However, it was determined that personal photos, resident registration numbers, mobile phone numbers, and home addresses were not stored on the server.
The Ministry of Foreign Affairs calculated the information related to one user ID as one record.
This implies that the information of up to 10,000 individuals may have been leaked.
However, the Ministry explained that it has not specified the exact scale of the breach, noting the possibility of duplicate IDs, but stated that it is "assuming that a significant amount of data has been leaked."
Regarding the entity behind the hacking attack, the Ministry of Foreign Affairs explained that there is currently insufficient technical analysis to draw a definitive conclusion, but the atmosphere suggests that the possibility of an information theft attempt by North Korea has not been ruled out.
It has been confirmed that the affected server is separated from the Ministry of Foreign Affairs' other internal networks and the networks of other government agencies.
Regarding the fact that the incident was made public five months after the site was blocked in February, another Ministry official explained, "As soon as we identified the breach, we blocked the infected parts of the server and conducted an investigation," adding, "We made the announcement after extensive review."
The Ministry of Foreign Affairs posted a notice regarding the hacking damage on its website yesterday and is preparing measures to individually notify the civil servants and other users of the system.